Security Incident
Definition
An event or chain of events that violates an organisation's security policy or credibly threatens the confidentiality, integrity, or availability of information assets. The declaration of an incident formally activates the incident response process.
- Trigger
- Violates policy or credibly threatens CIA of information assets
- Effect of declaration
- Formally activates the incident response process
- Origin
- One event or a chain of related events
Common questions
Who typically has authority to declare a security incident?+
A designated role, often the SOC lead or incident response manager, makes the formal declaration, since it triggers resourcing, notification and sometimes legal or regulatory obligations.
Can something be a security incident without any data actually being stolen?+
Yes, a credible threat to availability or integrity, such as ransomware encrypting files before any exfiltration is confirmed, is enough to meet the definition and start the response process.
Related terms
- Alert
- A notification generated when an event or pattern of events matches a detection rule. Alerts require triage to determine whether they represent...
- Data Breach
- An incident in which an unauthorised party gains access to, copies, or discloses protected data. Breaches trigger specific legal notification requirements under...
- Insider Threat
- An incident originating from a person with legitimate access to an organisation's systems, whether through malicious intent (data theft, sabotage) or negligence...
- Ransomware
- Malware that encrypts or exfiltrates data and demands payment for restoration or suppression. Modern ransomware incidents often combine an availability impact (encrypted...
- Security Event
- Any observable occurrence in a system or network. Events are the raw material from which alerts and incidents are identified; the vast...